CVE-2016-8581

MEDIUM

AlienVault OSSIM & USM <5.3.2 - XSS

Title source: llm
STIX 2.1

Description

A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Peter Lapp · textwebappsphp
https://www.exploit-db.com/exploits/40683
metasploit WORKING POC EXCELLENT
by Sasha Zivojinovic · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/alienvault_sqli_exec.rb

Scores

CVSS v3 6.1
EPSS 0.6815
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
alienvault/open_source_security_information_and_event_management < 5.3.1
alienvault/unified_security_management < 5.3.1
Published Oct 28, 2016
Tracked Since Feb 18, 2026